aidlc
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes local orchestration tools and an engine binary (referenced via the
{{INVOKE}}placeholder) to manage development states, logs, and workflow transitions. It incorporates explicit logic for shell-safe argument escaping (supporting both POSIX and PowerShell quoting) when passing user-provided text to these commands. - [INDIRECT_PROMPT_INJECTION]: The orchestrator has a inherent attack surface as it processes data from external tool directives, project files, and user input.
- Ingestion points: Ingests data from orchestration directives (e.g.,
narration,question,rules_content), user-supplied arguments, and project-local files likestage_fileandconsumesmanifests. - Boundary markers: The instructions mandate verbatim reproduction of tool-generated narration and use structured question rendering (via
AskUserQuestion) to maintain clear separation between system instructions and external content. - Capability inventory: The skill is capable of executing shell commands, reading project files, and dispatching tasks to sub-agents.
- Sanitization: It implements shell-safe escaping for user-supplied strings to mitigate command injection risks at the interface with local tools.
- [DYNAMIC_EXECUTION]: The skill dynamically dispatches work to specialized agent personas (e.g.,
aidlc-product-agent,aidlc-architect-agent) using aTask()mechanism based on the current workflow stage and instructions provided by the local orchestration engine. This behavior is standard for a multi-agent workflow system and is governed by a central conductor persona.
Audit Metadata